Secure Edge Computing with Lightweight Control-Flow Property-based Attestation
Title | Secure Edge Computing with Lightweight Control-Flow Property-based Attestation |
Publication Type | Conference Paper |
Year of Publication | 2019 |
Authors | Koutroumpouchos, Nikos, Ntantogian, Christoforos, Menesidou, Sofia-Anna, Liang, Kaitai, Gouvas, Panagiotis, Xenakis, Christos, Giannetsos, Thanassis |
Conference Name | 2019 IEEE Conference on Network Softwarization (NetSoft) |
Keywords | attack landscape, attestation, cloud computing, cloud devices, composability, Control-Flow Property-based Attestation, critical software components, decentralized solution, defense mechanism, device-integrity, Hardware, Human Behavior, industrial IoT applications, intelligent edge computing systems, Internet of Things, lightweight dynamic control-flow property-based attestation architecture, operational assurance, Protocols, pubcrawl, remote attestation, remote device, Resiliency, resource-constrained edge services, run-time modifications, Scalability, secure edge computing, security, security mechanisms, security of data, Software, software assurance, software integrity, software-based attacks, Trusted Component |
Abstract | The Internet of Things (IoT) is rapidly evolving, while introducing several new challenges regarding security, resilience and operational assurance. In the face of an increasing attack landscape, it is necessary to cater for the provision of efficient mechanisms to collectively verify software- and device-integrity in order to detect run-time modifications. Towards this direction, remote attestation has been proposed as a promising defense mechanism. It allows a third party, the verifier, to ensure the integrity of a remote device, the prover. However, this family of solutions do not capture the real-time requirements of industrial IoT applications and suffer from scalability and efficiency issues. In this paper, we present a lightweight dynamic control-flow property-based attestation architecture (CFPA) that can be applied on both resource-constrained edge and cloud devices and services. It is a first step towards a new line of security mechanisms that enables the provision of control-flow attestation of only those specific, critical software components that are comparatively small, simple and limited in function, thus, allowing for a much more efficient verification. Our goal is to enhance run-time software integrity and trustworthiness with a scalable and decentralized solution eliminating the need for federated infrastructure trust. Based on our findings, we posit open issues and challenges, and discuss possible ways to address them, so that security do not hinder the deployment of intelligent edge computing systems. |
DOI | 10.1109/NETSOFT.2019.8806658 |
Citation Key | koutroumpouchos_secure_2019 |
- security
- operational assurance
- Protocols
- Remote Attestation
- remote device
- resource-constrained edge services
- run-time modifications
- Scalability
- secure edge computing
- lightweight dynamic control-flow property-based attestation architecture
- security mechanisms
- security of data
- Software
- software assurance
- software integrity
- software-based attacks
- Trusted Component
- critical software components
- pubcrawl
- Human behavior
- Resiliency
- attack landscape
- Cloud Computing
- cloud devices
- composability
- Control-Flow Property-based Attestation
- attestation
- decentralized solution
- defense mechanism
- device-integrity
- Hardware
- industrial IoT applications
- intelligent edge computing systems
- Internet of Things